Permission receipt
Read-only bank feed
Transactions: allowed
Dates, descriptions, amounts, currencies, and transaction status for categorization, bookkeeping, reconciliation, and reporting. Stripe also supplies the institution, account type or nickname, and last four digits needed to identify the selected account.
Balances: authorized, not active
Current and available balance access is reserved solely for a future bank- reconciliation workflow. Rentium does not currently prefetch, refresh, retrieve, store, or display balances.
Ownership / full account numbers / money movement: not requested.
Stripe authenticates access inside its hosted institution flow. Rentium requests no ACH credentials, verification or tokenization product, payment initiation, or debit authorization through this read-only connection. Those bank-feed permissions remain separate from rent-payment setup and money movement.
Feed provider: Stripe Financial Connections. Disconnecting stops future feed access; it does not itself delete data previously shared with or retained by Rentium or Stripe.
See the privacy deletion process for requests involving data Rentium controls. Stripe retention remains subject to its own terms and applicable law.
Control 01
The data needed to run your rental books
- Account and workspace data: sign-in identifiers, profile information, workspace membership, roles, and consent evidence.
- Rental and accounting data: owners, properties, units, tenants, leases, charges, payments, categories, notes, reconciliations, and reports you create or import.
- Read-only bank-feed data: transaction dates, descriptions, signed amounts, currencies, lifecycle status, and limited identification metadata such as institution, account type or nickname, and last four digits. Rentium also requests permission to access current and available balances solely for a future bank-reconciliation workflow, but does not currently prefetch, refresh, retrieve, store, or display balances.
- Connected communications: when a staff member connects Quo, Rentium stores encrypted OAuth credentials and limited connection metadata. At that person's direction, the assistant can request the calls, messages, contacts, inboxes, or tasks that Quo makes available to the connected account.
- Service and security data: operational events, device or request information, and diagnostics needed to provide, protect, and troubleshoot the service—without raw bank transaction content in logs or analytics.
Control 02
Product use stays tied to the purpose you chose
Rentium uses account and workspace data to authenticate users, enforce access, operate the service, communicate about the account, prevent abuse, and meet legal obligations. Rental and accounting data is used to provide the portfolio, ledger, rent, and reporting workflows you request.
Bank transaction data is used only for the consenting landlord's categorization, bookkeeping, reconciliation, and reporting. Balance access is reserved solely for bank reconciliation if that workflow is enabled. Authorized users can view transaction data through authenticated, workspace-scoped Rentium UI and REST endpoints when they have the required portfolio capability.
When the independently gated bank-agent path is enabled, authorized users may use limited bank transaction data through Rentium's built-in assistant or a tool or agent they choose to connect, with the same permissions. These surfaces can review or code imported activity, match it to exact existing accounting, map rent-payment settlement accounting to an already-connected feed, manage typed deterministic rules, and request a refresh. A match is not statement reconciliation, and a settlement mapping does not change the provider bank account. They cannot link, complete, or disconnect bank feeds; retrieve balances, full account details, credentials, or identity documents; or move money.
These are ordinary authenticated API requests made at the user's direction, not a second bank-connection consent pathway. Rentium does not sell bank transaction data or use it to train models. When enabled, built-in assistant bank requests use no-collection and zero-data-retention routing. Data a user directs Rentium to send to an external tool or agent is then subject to that provider's retention, training, location, and subprocessor terms. Bank data remains excluded from analytics, error reporting, logs, email, support tooling, and other incidental telemetry.
A Quo connection is personal to one staff member and does not give teammates that person's grant. Only a Quo tool explicitly marked read-only may answer directly; sending a message, changing a contact or task, or using any tool without an unambiguous read-only annotation pauses for the staff member to review and approve the exact action. Requested Quo results become part of the built-in assistant turn and stored chat history and use Rentium's global no-collection and zero-data-retention model-routing settings. Rentium does not use connected communications to train models. See the Quo integration guide for the complete connection and approval boundary.
Control 04
Server-side Connections Data stays in the 50 states and D.C.
Rentium's location commitment applies to provider and server-side storage of Stripe Connections Data—including server-side replicas, backups, logs, and derived copies. Those systems remain within the 50 U.S. states and the District of Columbia unless Stripe approves another location in writing.
An authorized user may view or download their data on a device from another location. User-controlled device access and local copies are outside that server-side storage claim. The same is true when a user directs Rentium to deliver limited transaction data to an external tool or agent: that provider's terms govern its copy after delivery. Rentium reviews providers it appoints to process customer data for their safeguards, location, retention, subprocessors, incident terms, and contract.
Control 05
Disconnecting stops access; it does not rewrite the books
Disconnecting a bank feed tells Rentium and Stripe to stop future financial-account access and transaction refreshes. It does not itself delete Connections Data previously shared with or retained by Rentium or Stripe. Transactions already imported may remain as the landlord's accounting history so completed books, reconciliations, and reports do not silently change.
Disconnecting Quo removes Rentium's saved OAuth grant, asks Quo to revoke it, and removes Quo tools from future assistant turns. It does not delete messages, calls, contacts, or tasks held by Quo, or rewrite assistant conversations that already used a requested result.
Product data is retained only while needed for the authorized product purpose, legitimate business operations, legal or accounting requirements, or an active legal hold. Consent evidence is kept during the Stripe agreement and for at least 24 months after it ends. When no permitted purpose remains, data and reachable derived copies are deleted as reasonably feasible under the backup lifecycle.
Today, an owner with retained bank-data consent evidence or transaction history cannot be deleted in place. The feed can be disconnected; removing historical books or detaching retained consent evidence requires a separate, explicit retention and export workflow.
Control 06
Access, correction, export, deletion, and revocation
- Choose whether to connect a bank feed and which rental owner receives it.
- Disconnect a feed at any time to stop future financial-account access.
- Connect or disconnect personal Quo access, and approve or reject each proposed Quo write before it runs.
- Request access to, correction of, export of, or deletion of personal data, subject to identity verification and legal, security, consent-evidence, and accounting-record exceptions.
- Manage workspace membership and permissions through Rentium's access controls.
A deletion request to Rentium covers data Rentium controls. Stripe may retain data under its own terms or legal obligations; Rentium will coordinate a provider request where its obligations require that, but cannot promise deletion beyond those terms.
State or federal law may provide additional rights, including appeal or complaint options. Rentium will respond according to the law that applies to the verified request.
Control 07
A request channel before live collection
A dedicated public privacy-request address has not yet been published. Rentium will add it here before live bank-data collection begins. Private-preview users should use the support channel supplied with their account and should not include bank credentials or raw transaction details in a request.
This notice is version-controlled. A material change to the purpose, scope, sharing, security, or retention of bank data requires provider review, an updated disclosure, and new user consent before the change takes effect.